The weDownload Manager

The weDownload Manager

Known Toolbar

by weDownload Ltd

What is The weDownload Manager?

The weDownload Manager is software application developed by weDownload Ltd. It is most commonly found on computers running Windows 7 with nearly 55.17% of installations running this operating system. The weDownload Manager's installer is typically 9.00 MB in size and installs around 407 files. The most common release is 1.34.2.13 with 27.20% of all installations currently using this version.

The weDownload Manager is most popular in the United States with 63.52% of installations residing in this country.

The weDownload Manager adds 6 scheduled tasks to the Windows Task Scheduler launching the program at randomly scheduled times.

About The weDownload Manager?

WeDownload Manager is a software download distribution utility that facilitates the installation of various adware and toolbar offerings, including the Ominent Toolbar. The software is distributed using the Soft32 downloader and is commonly packaged with legitimate software products on distribution websites such as todownload.com, soft32.com, xtremedownload.com, free-downloads.us.com, and others.

Multiple virus scanners have detected malware in The weDownload Manager.

36cba358-e418-425b-9436-da3d2d9081fc-4.exe (MD5: c962db0aae4344d8a79329b396dda2c5) has been flagged by 44 scanners:
Scanner Software Result
Lavasoft Ad-Aware Trojan.Generic.11492923
Avira AntiVir Adware/CrossRider.A.17898
Antiy-AVL Trojan/Win32.TSGeneric
Baidu-International Adware.Win32.CrossRider.bAK
Bitdefender Trojan.Generic.11492923
Emsisoft Anti-Malware Trojan.Generic.11492923 (B)
ESET-NOD32 a variant of Win32/Toolbar.CrossRider.AK
Fortinet FortiGate Riskware/Toolbar_CrossRider
F-Secure Trojan.Generic.11492923
G Data Trojan.Generic.11492923
IKARUS anti.virus AdWare.Adload
K7 AntiVirus Trojan ( 0049c2a41 )
K7GW Trojan ( 0049c2a41 )
Malwarebytes PUP.Optional.weDownload.A
McAfee Artemis!C962DB0AAE43
McAfee-GW-Edition Artemis!C962DB0AAE43
MicroWorld-eScan Trojan.Generic.11492923
NANO AntiVirus Riskware.Win32.AdLoad.dcccgv
Panda Antivirus Trj/Genetic.gen
Sophos weDownload Manager
Symantec WS.Reputation.1
TrendMicro-HouseCall Suspicious_GEN.F47V0708
VIPRE Antivirus Crossrider (fs)
AVG Generic.D77
AVware Crossrider (fs)
CAT-QuickHeal AdWare.NSIS.r5 (Not a Virus)
Dr.Web Trojan.Crossrider.28616
Kaspersky not-a-virus:AdWare.NSIS.Adwapper.ai
Kingsoft AntiVirus Win32.Troj.Generic.a.(kcloud)
Rising Antivirus PE:Trojan.Win32.Generic.1733098B!389220747
Vba32 AntiVirus AdWare.Adwapper
Zillya Trojan.GoogUpdate.Win32.958
Comodo Security ApplicUnwnt
F-Prot W32/A-eb9ef301!Eldorado
AhnLab-V3 PUP/Win32.CrossRider
avast! Win32:Adware-gen [Adw]
Avira Adware/CrossRider.pq
Qihoo-360 HEUR/Malware.QVM10.Gen
Tencent Nsis.Adware.Adwapper.Edxj
Jiangmin Trojan.NSIS.GoogUpdate.br
SUPERAntiSpyware Adware.Crossrider/Variant
Bkav FE W32.CrossRider.Trojan
Agnitum Outpost PUA.Toolbar.CrossRider!
Trend Micro TROJ_MOSERAN.BMC
36cba358-e418-425b-9436-da3d2d9081fc-2.exe (MD5: 23a199f47a2803d225e1aa9d0c7265ce) has been flagged by 43 scanners:
Scanner Software Result
Lavasoft Ad-Aware Trojan.Generic.11493082
Avira AntiVir Adware/CrossRider.A.17820
Baidu-International Adware.Win32.CrossRider.BAJ
Bitdefender Trojan.Generic.11493082
Emsisoft Anti-Malware Trojan.Generic.11493082 (B)
ESET-NOD32 a variant of Win32/Toolbar.CrossRider.AJ
Fortinet FortiGate Riskware/Toolbar_CrossRider
F-Prot W32/A-eb9ef301!Eldorado
G Data Trojan.Generic.11493082
IKARUS anti.virus AdWare.Adload
K7 AntiVirus Trojan ( 0049bf0b1 )
K7GW Trojan ( 0049bf0b1 )
Malwarebytes PUP.Optional.weDownload.A
McAfee Artemis!23A199F47A28
MicroWorld-eScan Trojan.Generic.11493082
NANO AntiVirus Riskware.Win32.AdLoad.dcccgn
Rising Antivirus PE:Malware.Obscure!1.9C59
Sophos weDownload Manager
TrendMicro-HouseCall Suspicious_GEN.F47V0708
VIPRE Antivirus Crossrider (fs)
Zillya Adware.AdLoad.Win32.145
AVG Generic.16F
AVware Crossrider (fs)
Dr.Web Trojan.Crossrider.27022
F-Secure Gen:Variant.Adware.Kazy.374062
Kingsoft AntiVirus Win32.Troj.NSIS.br.(kcloud)
McAfee-GW-Edition Artemis!42AA1E814AAD
Panda Antivirus Trj/Genetic.gen
AhnLab-V3 PUP/Win32.CrossRider
Comodo Security ApplicUnwnt
Qihoo-360 Win32/Virus.Adware.ab1
Antiy-AVL GrayWare[AdWare:not-a-virus]/Win32.AdLoad
Avira Adware/CrossRider.pq
Kaspersky not-a-virus:AdWare.NSIS.Adwapper.ai
Symantec WS.Reputation.1
avast! Win32:Adware-gen [Adw]
Tencent Nsis.Trojan.Googupdate.Hvja
Vba32 AntiVirus Trojan.GoogUpdate
Jiangmin Trojan.NSIS.GoogUpdate.br
SUPERAntiSpyware Adware.Crossrider/Variant
Bkav FE W32.CrossRider.Trojan
Agnitum Outpost PUA.Toolbar.CrossRider!
Trend Micro TROJ_MOSERAN.BMC
36cba358-e418-425b-9436-da3d2d9081fc-11.exe (MD5: f5ced9cc2796ee9c23dec14034fbe333) has been flagged by 43 scanners:
Scanner Software Result
Lavasoft Ad-Aware Trojan.Generic.11481131
Avira AntiVir Adware/CrossRider.A.17803
Antiy-AVL GrayWare[AdWare:not-a-virus]/Win32.AdLoad
Baidu-International Adware.Win32.CrossRider.BAK
Bitdefender Trojan.Generic.11481131
Emsisoft Anti-Malware Trojan.Generic.11481131 (B)
ESET-NOD32 a variant of Win32/Toolbar.CrossRider.AK
Fortinet FortiGate Riskware/Toolbar_CrossRider
F-Secure Trojan.Generic.11481131
G Data Trojan.Generic.11481131
IKARUS anti.virus AdWare.Adload
K7 AntiVirus Trojan ( 0049c2a41 )
K7GW Trojan ( 0049c2a41 )
Malwarebytes PUP.Optional.weDownload.A
MicroWorld-eScan Trojan.Generic.11481131
NANO AntiVirus Riskware.Win32.AdLoad.dcbzfn
Panda Antivirus Trj/Genetic.gen
Sophos weDownload Manager
TrendMicro-HouseCall Suspicious_GEN.F47V0708
VIPRE Antivirus Crossrider (fs)
Zillya Adware.AdLoad.Win32.146
AhnLab-V3 PUP/Win32.CrossRider
AVG Generic.D77
Avira Adware/CrossRider.pq
AVware Crossrider (fs)
Dr.Web Trojan.Crossrider.33024
Kaspersky not-a-virus:AdWare.NSIS.Adwapper.ai
Qihoo-360 Win32/Virus.Adware.970
Rising Antivirus PE:Malware.Obscure!1.9C59
Symantec WS.Reputation.1
avast! Win32:Adware-gen [Adw]
McAfee Artemis!628509A3A09B
McAfee-GW-Edition Artemis!628509A3A09B
Kingsoft AntiVirus Win32.Troj.Generic.a.(kcloud)
Tencent Nsis.Trojan.Googupdate.Hvja
Vba32 AntiVirus Trojan.GoogUpdate
Comodo Security ApplicUnwnt
F-Prot W32/A-b38b90e7!Eldorado
Jiangmin Trojan.NSIS.GoogUpdate.br
SUPERAntiSpyware Adware.Crossrider/Variant
Bkav FE W32.CrossRider.Trojan
Agnitum Outpost PUA.Toolbar.CrossRider!
Trend Micro TROJ_MOSERAN.BMC
2edc0289-cc77-43d7-96a7-b05654baac3c-7.exe (MD5: b13418f26b6e71870ca997aaa2c59003) has been flagged by 40 scanners:
Scanner Software Result
AVG Generic.D77
Avira Adware/CrossRider.pq
AVware Crossrider (fs)
Dr.Web Trojan.Crossrider.31451
ESET-NOD32 a variant of Win32/Toolbar.CrossRider.AM
Fortinet FortiGate Adware/Adwapper
G Data Win32.Adware.Crossrider.M
IKARUS anti.virus Trojan.GoogUpdate
Kaspersky not-a-virus:AdWare.NSIS.Adwapper.ai
Kingsoft AntiVirus Win32.Troj.Generic.a.(kcloud)
Malwarebytes PUP.Optional.weDownload.A
NANO AntiVirus Riskware.Win32.Crossrider.devuka
Panda Antivirus Trj/Genetic.gen
Qihoo-360 HEUR/Malware.QVM10.Gen
Sophos weDownload Manager
Tencent Nsis.Adware.Adwapper.Pbyi
VIPRE Antivirus Crossrider (fs)
McAfee Artemis!C0481281D3F5
McAfee-GW-Edition Artemis
AhnLab-V3 PUP/Win32.CrossRider
K7 AntiVirus Adware ( 004a970a1 )
K7GW Adware ( 004a970a1 )
avast! Win32:Crossrider-N [PUP]
Baidu-International Trojan.Win32.GoogUpdate.AlQp
F-Prot W32/A-04c00d5a!Eldorado
TrendMicro-HouseCall Suspicious_GEN.F47V0809
Lavasoft Ad-Aware Gen:Variant.Adware.Kazy.374062
Bitdefender Gen:Variant.Adware.Kazy.374062
Emsisoft Anti-Malware Gen:Variant.Adware.Kazy.374062 (B)
F-Secure Gen:Variant.Adware.Kazy.374062
MicroWorld-eScan Gen:Variant.Adware.Kazy.374062
Rising Antivirus PE:Malware.Obscure!1.9C59
Antiy-AVL GrayWare[AdWare:not-a-virus]/NSIS.Adwapper
Zillya Trojan.GoogUpdate.Win32.1952
Avira AntiVir ADWARE/CrossRider.Gen2
Symantec Adware.Crossid!gen1
SUPERAntiSpyware Adware.Crossrider/Variant
Bkav FE W32.CrossRider.Trojan
Agnitum Outpost PUA.Toolbar.CrossRider!
Trend Micro TROJ_MOSERAN.BMC
2edc0289-cc77-43d7-96a7-b05654baac3c-6.exe (MD5: cb3c4477f6aa2333d801987a47af5221) has been flagged by 40 scanners:
Scanner Software Result
AVG Generic.D77
Avira Adware/CrossRider.pq
AVware Crossrider (fs)
Dr.Web Trojan.Crossrider.31452
ESET-NOD32 a variant of Win32/Toolbar.CrossRider.AP
G Data Win32.Adware.Crossrider.M
IKARUS anti.virus PUA.PlusHD
Kaspersky not-a-virus:AdWare.NSIS.Adwapper.ai
Kingsoft AntiVirus Win32.Troj.Generic.a.(kcloud)
Malwarebytes PUP.Optional.weDownload.A
McAfee Artemis!CB3C4477F6AA
McAfee-GW-Edition BehavesLike.Win32.BadFile.th
Panda Antivirus Trj/Chgt.F
Qihoo-360 Win32/Virus.Adware.970
Sophos Generic PUA EA
Tencent Nsis.Adware.Adwapper.Syrs
VIPRE Antivirus Crossrider (fs)
avast! Win32:Crossrider-N [PUP]
Baidu-International Trojan.Win32.GoogUpdate.AlQp
Fortinet FortiGate W32/GoogUpdate.AE!tr
F-Prot W32/A-04c00d5a!Eldorado
TrendMicro-HouseCall Suspicious_GEN.F47V0809
Lavasoft Ad-Aware Gen:Variant.Adware.Kazy.374062
Bitdefender Gen:Variant.Adware.Kazy.374062
Emsisoft Anti-Malware Gen:Variant.Adware.Kazy.374062 (B)
F-Secure Gen:Variant.Adware.Kazy.374062
MicroWorld-eScan Gen:Variant.Adware.Kazy.374062
Rising Antivirus PE:Malware.Obscure!1.9C59
AhnLab-V3 PUP/Win32.CrossRider
Antiy-AVL GrayWare[AdWare:not-a-virus]/NSIS.Adwapper
NANO AntiVirus Trojan.Win32.GoogUpdate.deofza
K7 AntiVirus Adware ( 004a90bb1 )
K7GW Adware ( 004a90bb1 )
Zillya Trojan.GoogUpdate.Win32.1952
Avira AntiVir ADWARE/CrossRider.Gen2
Symantec Adware.Crossid!gen1
SUPERAntiSpyware Adware.Crossrider/Variant
Bkav FE W32.CrossRider.Trojan
Agnitum Outpost PUA.Toolbar.CrossRider!
Trend Micro TROJ_MOSERAN.BMC

Software Behaviors

Scheduled tasks:
  • b9a50c40-f2cc-420c-be6f-593440d8deaa-6.exe is scheduled as a task named '731b28ed-138e-45a5-af8b-7ef590e61293-6'.
  • The weDownload Manager-codedownloader.exe is scheduled as a task named 'ebed045b-11c2-47a7-bae0-1f07ff30e3c0-7'.
  • ebed045b-11c2-47a7-bae0-1f07ff30e3c0-6.exe is scheduled as a task named 'temp_ebed045b-11c2-47a7-bae0-1f07ff30e3c0-6'.
  • ebed045b-11c2-47a7-bae0-1f07ff30e3c0-2.exe is scheduled as a task named 'temp_ebed045b-11c2-47a7-bae0-1f07ff30e3c0-2'.
  • bc39018e-d2de-4d68-aa32-0afacbc16f5f-2.exe is scheduled as a task named 'temp_bc39018e-d2de-4d68-aa32-0afacbc16f5f-2'.
  • 03091666-40b5-44af-b8b1-7438214ece0b-4.exe is scheduled as a task named '03091666-40b5-44af-b8b1-7438214ece0b-4'.

Startup Entries

Startup tasks:
  • b9a50c40-f2cc-420c-be6f-593440d8deaa-6.exe is automatically launched at startup through a scheduled task named 5d2076bc-d559-4c68-aca0-29a2e5982b96-7.
  • The weDownload Manager-nova.exe is automatically launched at startup through a scheduled task named 09d2f095-b00b-4e2a-8f47-83a824a7126a-7.
  • The weDownload Manager-novainstaller.exe is automatically launched at startup through a scheduled task named 1fb50b06-6845-4d15-b2d8-32c25ced1291-6.
  • 1fb50b06-6845-4d15-b2d8-32c25ced1291-11.exe is automatically launched at startup through a scheduled task named 1fb50b06-6845-4d15-b2d8-32c25ced1291-3.
  • 2e18c836-5212-44f2-b4dd-c1ea360752fb-7.exe is automatically launched at startup through a scheduled task named 2e18c836-5212-44f2-b4dd-c1ea360752fb-1.
  • 2e18c836-5212-44f2-b4dd-c1ea360752fb-5.exe is automatically launched at startup through a scheduled task named 2e18c836-5212-44f2-b4dd-c1ea360752fb-5_user.

Software Details

URL:
https://www.wedownload.com
Support:
–
Installation path:
C:\Program Files\the wedownload manager
Uninstaller:
C:\Program Files\The weDownload Manager\Uninstall.exe /fromcontrolpanel=1
Size:
9.00 MB
Language:
English

The weDownload Manager Executable Details

Primary executable:
utils.exe
Name:
The weDownload Manager
Path:
C:\Program Files\the wedownload manager\utils.exe
MD5:
–
SHA-1:
–
SHA-256:
–
Files installed by The weDownload Manager
File Type Filename MD5
EXE
94977dabd2451b8aafa5cca082a0c55c
EXE
9f2c4d686c8cf36ae9ba6eead6f1fb91
EXE
333724305e96620d2a63ba179b93ece5
EXE
0a94c20d589cea184ca31bcaa37b9231
EXE
21dfbf105a76aba0cac435d4a81da107
EXE
d7afe6a8d4534987636026696a68f5bf
EXE
8e804f8acb0a5dce28f3c4a16af60998
EXE
e6ed8fd5a4feb42759b627bc340487d2
EXE
7ffb956c13dc80ae774d04363f5cbb0e
EXE
ca5f41eae30f252599ccaf9cd9a73314